2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68747 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF on kernel BO VA nodes If the ... |
| CVE-2025-68746 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: tegra210-quad: Fix timeout handling When the ... |
| CVE-2025-68745 | CRITICAL | 9.8 | 0.1% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clear cmds after chip reset Commit ... |
| CVE-2025-68744 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Free special fields when update [lru_,]percpu_... |
| CVE-2025-68743 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: mshv: Fix create memory region overlap check The c... |
| CVE-2025-68742 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix invalid prog->stats access when update_eff... |
| CVE-2025-68741 | CRITICAL | 9.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix improper freeing of purex item ... |
| CVE-2025-68740 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: ima: Handle error code returned by ima_filter_rule_... |
| CVE-2025-68739 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: PM / devfreq: hisi: Fix potential UAF in OPP handli... |
| CVE-2025-68738 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix null pointer deref in mt799... |
| CVE-2025-68737 | — | — | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: arm64/pageattr: Propagate return value from __chang... |
| CVE-2025-68736 | HIGH | 8.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: landlock: Fix handling of disconnected directories ... |
| CVE-2025-68735 | HIGH | 7.8 | 0.2% | Dec 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Prevent potential UAF in group creatio... |
| CVE-2025-68608 | HIGH | 7.5 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in DeluxeThemes Userpro userpro allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-68606 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPXPO PostX ultimate-post al... |
| CVE-2025-68605 | MEDIUM | 6.5 | 0.1% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post G... |
| CVE-2025-68603 | MEDIUM | 5.4 | 0.1% | Dec 24, 2025 | Missing Authorization vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows Exploiting Incorrectl... |
| CVE-2025-68602 | MEDIUM | 4.7 | 0.4% | Dec 24, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Strip... |
| CVE-2025-68601 | MEDIUM | 5.4 | 0.1% | Dec 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations ... |
| CVE-2025-68600 | MEDIUM | 4.9 | 0.1% | Dec 24, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Reques... |
| CVE-2025-68599 | MEDIUM | 6.5 | 0.1% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Embeds For YouTube... |
| CVE-2025-68598 | MEDIUM | 6.5 | 0.1% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page ... |
| CVE-2025-68597 | MEDIUM | 6.5 | 0.1% | Dec 24, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interact... |
| CVE-2025-68596 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Bit Apps Bit Assist bit-assist allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-68595 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Missing Authorization vulnerability in Trustindex Widgets for Social Photo Feed social-photo-feed-widget allows Exploiti... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now